ZeroHour
Threat actor

IndigoZebra

2 mentions in 7 days · 2 in 30 days · 2 total · first seen · last

Timeline

SilkParasite Infrastructure Links SpiceRAT to Central Asian Targets

Hunt.io linked SpiceRAT, NodeEdgeRAT, and NomadRAT C2 servers to the SilkParasite campaign targeting Central Asian governments since mid-2022.

Hunt.io and researcher Guy Yasur mapped C2 infrastructure tying three of seven RAT families from Bitdefender's SilkParasite report through shared TLS certificates, parent domains, and a cloned RTX Corporation homepage. One certificate spoofing Uzbekistan's state railway was issued by TLC, a CA funded by China's CAICT, and domains impersonate state entities in Turkmenistan, Uzbekistan, Tajikistan, and Kyrgyzstan. Passive DNS pushes the campaign back to mid-2022, and the infrastructure overlaps China-nexus activity including FamousSparrow and IndigoZebra.

Security Affairs · 1h agoThreat actor in the wild 3 sources

SilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia

Hunt.io links SpiceRAT C2 servers to China-nexus SilkParasite espionage targeting Central Asian governments, with related infrastructure active since 2022.

Hunt.io and researcher Guy Yasur traced a cluster of SpiceRAT command-and-control servers active from late 2025 to August 2026 to infrastructure linked to the China-nexus SilkParasite espionage operation. Shared parent domains, a certificate resembling an Uzbek railway entity, and a cloned RTX Corporation homepage appearing on 13 servers connect SpiceRAT systems to NodeEdgeRAT and NomadRAT infrastructure. Passive DNS records show related subdomains as early as mid-2022, suggesting the infrastructure has existed for at least four years. Hostnames impersonate government, energy and telecom targets across Turkmenistan, Tajikistan, Uzbekistan, Kyrgyzstan and Kazakhstan.

Cyber Security Newsupdated · 1h agofirst · 3h agoThreat actor in the wild 3 sources